A Privacy-Preserving Domain Adaptation Method under the End-Cloud Collaborative Learning Framework
By introducing domain adaptation mechanism, communication compression strategy, enhanced Transformer model update framework, differential privacy protection mechanism and iterative subsampling and weighting strategies into the end-cloud collaborative learning framework, the problems of non-independent and homogeneous data processing, data privacy protection, communication efficiency improvement and model performance imbalance in the existing technology are solved, and efficient, secure and flexible end-cloud collaborative learning is achieved.
Patent Information
- Application Number
- CN202410892522.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-04
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-07-04
AI Technical Summary
The existing end-cloud collaborative learning technology has shortcomings in processing non-independent and homogeneous data, protecting data privacy, improving communication efficiency and model performance.
A domain adaptation method for privacy protection under the framework of end-cloud collaborative learning is proposed. The model parameters are dynamically adjusted through the domain adaptation mechanism, the communication compression strategy is used to reduce the transmission amount of model updates, and the enhanced Transformer model update framework is used to improve the generalization capability of the model, and a differential privacy protection mechanism and iterative subsampling and heavy weighting strategy are introduced.
It significantly improves the generalization ability and learning efficiency of the model, reduces the communication cost during the model update process, ensures the security of data privacy of end devices, and is suitable for application scenarios that require end-cloud collaborative processing, privacy protection and high communication efficiency.
Smart Images

Figure CN118779913B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of end-cloud collaborative learning, and in particular to a privacy protection domain adaptation method under an end-cloud collaborative learning framework. Background Art
[0002] With the rapid development of smart devices and cloud computing technology, end-cloud collaborative learning has become an effective way to solve large-scale data processing problems. In the end-cloud collaborative learning framework, the end device is responsible for data collection and preliminary processing, and then uploads the information to the cloud for in-depth model training and optimization. This architecture aims to combine the distributed computing capabilities of the end device with the powerful computing resources of the cloud to achieve efficient execution of machine learning tasks. However, existing end-cloud collaborative learning technology solutions have several problems to be solved in practical applications, especially in processing non-independent and identically distributed (non-iid) data, protecting data privacy, and improving communication efficiency.
[0003] First, most end-cloud collaborative learning solutions assume that the data of the end device and the cloud data center are independent and identically distributed. However, in actual scenarios, due to the differences in the geographical location and operating environment of the end devices, the data collected by them are mostly non-independent and identically distributed. This inconsistency in data distribution limits the generalization performance of the cloud model, because the model may be difficult to adapt to the specific data characteristics of all end devices. Secondly, the data generated by the end device may contain sensitive information, such as personal health data or location information. Existing technical solutions have obvious shortcomings in data privacy protection, and they may inadvertently leak users' private data during model training and updating. In addition, directly uploading raw data or model updates to the cloud may also increase the risk of data leakage. Furthermore, the communication overhead in end-cloud collaborative learning is also an issue that cannot be ignored. With the increase in the number of end devices and the expansion of the scale of model parameters, each model update requires a large amount of data transmission, which not only increases the network burden, but also may cause data transmission delays, thereby affecting learning efficiency. Finally, previous solutions often use simple averaging or weighting strategies when updating and aggregating models, and fail to fully consider the uniqueness and importance of data from different end devices. This simple aggregation strategy may lead to uneven model performance, especially when facing multiple clients with different data distribution and quality.
[0004] In summary, the existing technologies face the following main challenges and deficiencies in the end-cloud collaborative learning framework: 1) Insufficient handling of non-independent and identically distributed data: Failure to fully adapt to the data distribution differences on end devices, resulting in limited model generalization ability; 2) Inadequate data privacy protection: User privacy may be leaked during model training and updating, lacking effective privacy protection mechanisms; 3) Low communication efficiency: High communication overhead exists during model parameter updating and transmission, especially when end device resources are limited; 4) Unbalanced model performance: Aggregation strategies fail to fully consider the diversity and differences of client data, affecting the performance of the final model. Summary of the Invention
[0005] To solve the above technical problems, the present invention proposes a privacy-preserving domain adaptation method under an end-cloud collaborative learning framework. In the method, the domain adaptation mechanism can dynamically adjust model parameters according to the data distribution of end devices, improving the adaptability of the model to different data distributions; the communication compression strategy reduces the transmission volume of model updates through model quantization and sparse coding techniques, improving communication efficiency; the enhanced Transformer model update framework uses the self-attention mechanism to capture long-range dependencies in the data, and enhances the generalization ability of the model through an adversarial loss function and a pre-training fine-tuning strategy; the differential privacy protection mechanism introduces a random response mechanism during local model training to protect personal data from being leaked; the iterative subsampling and reweighting strategy optimizes the performance of the model on the target task through subsampling and weight adjustment, while reducing the number of samples and improving the generalization ability of the model. The present invention not only improves the generalization ability and learning efficiency of the model, but also reduces the communication cost during model updating, and ensures the security of end device data privacy, and is applicable to application scenarios that require end-cloud collaborative processing, privacy protection, and high communication efficiency, such as intelligent health monitoring, intelligent security monitoring and other intelligent system application scenarios.
[0006] To achieve the above object, the technical solution of the present invention is as follows:
[0007] A privacy-preserving domain adaptation method under an end-cloud collaborative learning framework, including an end device and a cloud server, comprising the following steps:
[0008] The end device collects training data and performs preprocessing to obtain a training data set;
[0009] The end device uses the domain adaptation mechanism to extract feature data from the training data set and dynamically adjust model parameters;
[0010] The terminal device transmits the feature data to the cloud server, and the cloud server performs model training and updating under the enhanced Transformer model update framework to obtain a trained cloud model; during the training process, the cloud server uses a communication compression strategy to optimize the transmission of model parameters and applies a differential privacy protection mechanism to protect patient privacy;
[0011] The cloud server optimizes the trained cloud model through an iterative subsampling and reweighting strategy, and distributes the optimized model to the terminal device as the final model;
[0012] The terminal device collects the data to be detected and inputs it into the final model to obtain the detection result.
[0013] Preferably, the preprocessing includes filtering, denoising, and normalization.
[0014] Preferably, the terminal device uses a domain adaptation mechanism to extract feature data from the training dataset and dynamically adjust the model parameters, including the following steps:
[0015] The adapter consists of L fully connected layers, each layer having N l neurons, where l = 1, 2, …, L, and each layer contains the ReLU activation function ReLU(x) = max(0, x), which can perform a non-linear transformation on the features. Let the feature vector of the input data be x, and the output of the domain adapter be z. Then the forward propagation of the adapter can be expressed as:
[0016] z = f adapter (x; θ adapter ) = W L ReLU(W L-1 …ReLU(W1x + b1)… + b L-1 ) + b L (2)
[0017] where, f adapter is the function of the adapter, W l and b l are the weight matrix and bias vector of the l-th layer respectively, and θ adapter = {W1, b1, …, W L , b L} are the parameters of the adapter;
[0018] The domain adaptation loss of the adapter is as follows:
[0019]
[0020] where, the domain adaptation loss is the maximum mean discrepancy MMD or KL divergence. When using the maximum mean discrepancy MMD, z S and zT They are the outputs of the source domain and target domain data after passing through the adapter respectively;
[0021] Let θ t be the model parameters at the current moment, be the gradient of the current loss function with respect to the model parameters, and v t be the momentum term at the current moment, and μ be the momentum parameter. Then the momentum update rule can be expressed as:
[0022]
[0023] where η is the learning rate; update the model parameters according to the updated momentum term v t+1 as follows:
[0024] θ t+1 = θ t - v t+1 (5)
[0025] The momentum term v t is usually initialized as a zero vector, i.e., v0 = 0.
[0026] Preferably, the cloud server performs model training and update under the enhanced Transformer model update framework, including the following steps:
[0027] Construct a pre-trained model Transformer based on multi-head attention as the starting point;
[0028] Input the feature data into the pre-trained model for training, and obtain the trained cloud model by further fine-tuning strategies to adapt to the target task and dataset:
[0029] Introduce an adversarial loss function. Therefore, the total loss function of the cloud model includes the adversarial loss domain adaptation loss and the target task loss of the model
[0030]
[0031] where λ1 and λ2 are used to balance the weights of the two losses, is the task-specific loss function, where M is the total number of categories, and y c is a vector, and its c-th element represents whether the true label is category c, and p c is the probability that the model predicts the sample belongs to category c.
[0032] Preferably, during the training process, the cloud server uses a communication compression strategy to optimize the transmission of model parameters, including the following steps:
[0033] Perform model quantization to convert floating - point parameters into low - precision representations. Let the original model parameter be \(W\) and the quantized parameter be \(W'\). The quantization process can be expressed as:
[0034] Divide, round(·) rounds to the nearest integer;
[0035] Adopt sparse coding technology to reduce the amount of data to be transmitted by only activating the important parts in model updates. Let the update vector be \(dW\) and the vector after sparse coding be \(dW'\). Then the sparse coding process can be expressed as:
[0036] \(dW'=\text{sparse}(dW,\tau)\ (14)\)
[0037] where \(\tau\) is the threshold for determining which parameters are important, and \(\text{sparse}(·,·)\) is the sparse coding operation;
[0038] Combine model quantization and sparse coding technologies to reduce the communication overhead of model updates. The combined communication volume \(C\) CommCost can be expressed as:
[0039] \(C\) CommCost \(=\text{size}(W')+\text{size}(dW')\ (15)\)
[0040] where the \(\text{size}(·,·)\) function represents the byte size of the parameters after quantization or sparse coding.
[0041] Preferably, it further includes the following steps: Let \(T\) be the transmission period, and perform regular transmission of the quantized and sparsely - coded model updates according to the preset transmission period. The transmission strategy can be expressed as:
[0042]
[0043] where \(W\) t is the model parameter at time step \(t\), and \(dW'\) i is the model update coded at time step \(i\).
[0044] Preferably, during the training process, the cloud server applies differential privacy protection mechanisms to protect patient privacy, including the following steps:
[0045] Introduce a random response mechanism in model training. Let \(b\) be a binary random variable, whose value is 1 representing the true response and 0 representing the false response. The random response \(r\) can be expressed as:
[0046] \(r = b+\epsilon\) r \((17)\)
[0047] where \(\epsilon\) r is from Random noise extracted from the distribution;
[0048] Quantify the information content of the parameters through differential privacy constraints. For each parameter θ j , calculate its Fisher information F(θ j ), and then dynamically adjust the noise σ according to the magnitude of the Fisher information j :
[0049]
[0050] where C g is a constant determined according to the global differential privacy budget ∈ and the security margin δ.
[0051] Preferably, the cloud server optimizes the trained cloud model through an iterative subsampling and reweighting strategy, including the following steps:
[0052] Subsample iteratively from the training dataset and adjust the sample weights according to the performance of the model on the target distribution. The weight adjustment formula is as follows:
[0053]
[0054] where W i,t is the weight of the i-th sample in the t-th iteration, is the loss of the model h on the sample x i , is the factor by which the learning rate η is scaled by the number of samples n.
[0055] Based on the above technical solutions, the beneficial effects of the present invention are:
[0056] 1) Enhance the model generalization performance: Through the domain adaptation mechanism, the present invention effectively addresses the non-independent and identically distributed problem of terminal device data, enabling the model to adapt to the characteristics of different data distributions, and thus significantly improving the generalization ability of the model on diverse datasets. On the MNIST-C data, compared with the existing method DAN, the method of the present invention improves by approximately 3% in terms of AP, significantly enhancing the generalization ability of the model on the unknown target domain.
[0057] 2) Reduce the communication cost: The present invention adopts a communication compression strategy, combined with model quantization and sparse coding techniques, significantly reducing the data transmission volume during the model update process. Compared with the existing method based on dynamic networks, the communication cost is reduced by more than 10%;
[0058] 3) Strengthen data privacy protection: The differential privacy protection mechanism of the present invention effectively protects the privacy of terminal device data through the random response mechanism to obfuscate personal data, while maintaining the prediction ability of the model;
[0059] 4) Improve the model update efficiency: The present invention utilizes iterative subsampling and reweighting strategies to optimize the performance of the model on the target task, reduce the number of samples, accelerate the convergence speed of the model, and enhance the efficiency of model update;
[0060] 5) Strongly adaptable edge-cloud collaboration: The method of the present invention does not depend on a specific data distribution, can adapt to the data characteristics of a variety of different edge devices, and enhances the adaptability and flexibility of edge-cloud collaborative learning;
[0061] 6) Reduce computational resource consumption: By applying model quantization and sparse coding, the present invention reduces the computational burden of the terminal device during model update, enabling resource-constrained devices to also participate in edge-cloud collaborative learning and expanding the application scope;
[0062] 7) Enhance system robustness: The present invention enhances the robustness of the model to small perturbations of input data by introducing an adversarial loss function, enabling the model to maintain stable performance in the face of data noise and outliers. Description of the Drawings
[0063] Figure 1 is a schematic flowchart of a privacy-preserving domain adaptation method under an edge-cloud collaborative learning framework in an embodiment. Detailed Embodiment
[0064] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention.
[0065] As Figure 1 shown, this embodiment provides a privacy-preserving domain adaptation method under an edge-cloud collaborative learning framework, including an edge device and a cloud server, and the implementation steps are as follows:
[0066] Step 1, the edge device collects training data and performs preprocessing to obtain a training data set.
[0067] In this embodiment, it is applied to an intelligent health monitoring system for real-time monitoring and analysis of the health status of patients. The edge device collects the physiological data of patients, such as heart rate, blood pressure, and body temperature, etc. However, it is not limited to this, and it can also be used in fields such as autonomous driving, intelligent manufacturing, and intelligent security, and can also be widely applied to application scenarios that require data privacy protection such as medical image analysis. The training data is collected according to the specific application field and scenario.
[0068] Preprocess the collected data, and the preprocessing includes but is not limited to filtering, denoising, and normalization.
[0069] Step 2, the edge device uses the domain adaptation mechanism to extract feature data from the training data set and dynamically adjust the model parameters.
[0070] In this embodiment, a domain adaptation mechanism is used. By introducing a learnable domain adapter, the model parameters are dynamically adjusted according to the distribution characteristics of the data. This mechanism allows the model to maintain excellent performance on data from different institutions while capturing and leveraging institution-specific features, thereby enhancing the generalization ability of the model.
[0071] Specifically, the design of the domain adapter is based on a neural network architecture, aiming to capture and adapt to the characteristics of different data distributions. The adapter consists of a series of fully connected layers, each layer containing an activation function that can perform a non-linear transformation on the features. Let the feature vector of the input data be x and the output of the domain adapter be z. Then the forward propagation of the adapter can be expressed as:
[0072] z = f adapter (x; θ adapter ) (1)
[0073] where f adapter is the function of the adapter and θ adapter is the parameter of the adapter. The adapter consists of L fully connected layers, each layer having N l neurons, where l = 1, 2, …, L. Each layer contains the ReLU activation function ReLU(x) = max(0, x), which can perform a non-linear transformation on the features. Let the feature vector of the input data be x and the output of the domain adapter be z. Then the forward propagation of the adapter can be further expressed as:
[0074] z = f adapter (x; θ adapter ) = W L ReLU(W L-1 …ReLU(W1x + b1)… + b L-1 ) + b L (2)
[0075] where W l and b l are the weight matrix and bias vector of the l-th layer respectively, and θ adapter = {W1, b1, …, W L , b L} is the parameter of the adapter.
[0076] To train the domain adapter, a loss function is defined, which can measure the performance difference of the model on different data distributions. The loss function can be the Maximum Mean Discrepancy (MMD) or the Kullback-Leibler (KL) divergence. Taking MMD as an example, the loss function can be expressed as:
[0077]
[0078] where z Sand z T are the outputs of the source domain and target domain data after passing through the adapter, respectively. MMD is a kernel method for measuring the similarity between two probability distributions.
[0079] Momentum update algorithm: The implementation of the domain adaptation module involves an end-to-end training process, which includes the update of the domain adapter parameters and the update of the model main body parameters. To improve the efficiency and quality of model training, the momentum update algorithm is used to update the parameters during the separate training of the model. The momentum update algorithm introduces a momentum term by calculating the exponentially weighted average of the gradients, which helps the model move more smoothly in the parameter space. Let θ t be the model parameters at the current moment, be the gradient of the current loss function with respect to the model parameters, v t be the momentum term at the current moment, and μ be the momentum parameter. Then the momentum update rule can be expressed as:
[0080]
[0081] where η is the learning rate; the model parameters are updated according to the updated momentum term v t+1 as follows:
[0082] θ t+1 = θ t - v t+1 (5)
[0083] The momentum update algorithm not only accelerates the convergence process of gradient descent but also increases the robustness of the model to gradient noise. In practical applications, the momentum term v t is usually initialized as a zero vector, i.e., v0 = 0.
[0084] Step 3, the end device transmits the feature data to the cloud server, and the cloud server performs model training and update under the enhanced Transformer model update framework to obtain the trained cloud model; during the training process, the cloud server uses a communication compression strategy to optimize the transmission of model parameters and applies a differential privacy protection mechanism to protect patient privacy.
[0085] In this embodiment, the cloud server adopts an enhanced Transformer model update framework, uses the self-attention mechanism to capture long-range dependencies in the data, and combines the adversarial loss function and the pre-training fine-tuning strategy to improve the generalization ability of the model. The following is the main process of the enhanced Transformer model update framework:
[0086] Self-attention mechanism: The self-attention mechanism is the core of the Transformer model, which allows the model to dynamically focus on different positions in the sequence when processing sequence data. The self-attention function can be expressed as:
[0087]
[0088] Among them, Q, K, and V are the Query, Key, and Value matrices respectively, and d k is the dimension of K, and the softmax(·,·) function is used to normalize the weights.
[0089] Multi-Head Attention: To enhance the capabilities of the model, a multi-head attention mechanism is introduced. It divides the input into multiple heads, and each head independently calculates the attention weights. The output of multi-head attention is the concatenation of the outputs of all heads:
[0090] MultiHead(Q, K, V) = Concat(head1, …, head h )W O (7)
[0091] where head i is the attention output of the i-th head, and W O is the weight matrix of the output.
[0092] Adversarial Loss Function: To improve the generalization ability of the model, an adversarial loss function is introduced. It trains the model by maximizing the robustness of the model to small perturbations of the input data. The adversarial loss can be expressed as:
[0093]
[0094] where is the data distribution, f is the forward propagation function of the model, is the loss function, r is the perturbation of the input data, and ∈ is the threshold of the perturbation.
[0095] Pre-training and Fine-tuning Strategy: The present invention can utilize a visual pre-trained model such as Transformer as a starting point and adapt to new tasks and datasets by further fine-tuning strategies on this model.
[0096] End-to-End Model Update: The update of the enhanced Transformer model is end-to-end, including the training of the self-attention mechanism, the optimization of the adversarial loss, and the domain adaptation loss. The goal of end-to-end training is to minimize the total loss function. Therefore, the loss function includes the adversarial loss domain adaptation loss and the target task loss of the model sum:
[0097]
[0098] where λ1 and λ2 are used to balance the weights of the two losses. is a task-specific loss function (cross-entropy loss), where M is the total number of classes, and y c is a vector whose c-th element indicates whether the true label is class c (usually 0 or 1), and p c is the probability that the model predicts the sample belongs to class c.
[0099] Step 4, the cloud server optimizes the trained cloud model through the iterative subsampling and reweighting strategy, and distributes the optimized model to the edge device as the final model.
[0100] In this embodiment, the cloud server optimizes the trained cloud model by using the iterative subsampling and reweighting strategy. The main process of its iterative subsampling and reweighting strategy is as follows:
[0101] Subsampling mechanism: The subsampling mechanism involves randomly extracting a smaller subset from the original training dataset for training or evaluating the model. Let be the original dataset, be the subsampled dataset, and the subsampling process F sub (·,·) can be expressed as:
[0102]
[0103] where n is the number of samples extracted.
[0104] Performance evaluation and weight adjustment: Based on subsampling, evaluate the performance of the model on the subsampled dataset and adjust the sample weights accordingly. The purpose of weight adjustment is to increase the weights of samples that are informative for the target task. The performance evaluation function P(h,x i ) is used to measure the performance of the model h on the sample x i , usually the accuracy of the model on this sample or the negative value of the loss. The weight adjustment is based on the performance evaluation to increase the weights of samples that are informative for the target task. The weight adjustment process can be expressed as:
[0105] W i,t+1 =W i,t ·exp(η·P(h,x i )) (11)
[0106] where W i,t is the weight of the i-th sample in the t-th iteration, and η is the learning rate that controls the magnitude of weight adjustment.
[0107] Multiplicative weight update algorithm: To implement the iterative subsampling and reweighting strategy, the multiplicative weight update algorithm (MW) is adopted. The MW algorithm iteratively adjusts the weights to make the model pay more attention to the informative parts for the target task. The update rule of the MW algorithm can be expressed as:
[0108]
[0109] where W i,t is the weight of the i-th sample in the t-th iteration, is the loss of the model h on the sample x i and is the factor by which the learning rate η is scaled by the number of samples n.
[0110] The multiplicative weight update algorithm is different from the momentum update algorithm. The former focuses on dynamically adjusting the sample weights according to the performance of the model on the subsampled dataset, while the latter aims to assist gradient descent through the total loss function to enhance the robustness to noise. is the factor by which the learning rate η is scaled by the number of samples n.
[0111] Privacy-preserving subsampling: In the context of differential privacy, the subsampling process needs to consider privacy protection. This means that subsampling cannot depend on any single data point to avoid privacy leakage. Privacy-preserving subsampling can be achieved by adding random noise or using privacy-preserving algorithms.
[0112] Step 5, the end device collects the data to be detected and inputs it into the final model to obtain the detection result.
[0113] In this embodiment, the end device analyzes the current health status of the patient through the final model in the end device and provides corresponding medical advice.
[0114] In one embodiment, there is also provided a processing process in which the cloud server uses a communication compression strategy to optimize the transmission of model parameters and applies a differential privacy protection mechanism to protect the privacy of patients during the training process, which specifically includes the following:
[0115] 1) The main process of using a communication compression strategy to optimize the transmission of model parameters:
[0116] Model quantization technology: Model quantization is a method to reduce the representation precision of model parameters, which can convert floating-point parameters into low-precision representations, thereby reducing the model size. Let the original model parameter be W, and the quantized parameter be W'. The quantization process can be expressed as:
[0117]
[0118] where bits represents the number of quantization bits, quantize(·,·) is the quantization operation, is the quantization interval, and round(·) is rounding to the nearest integer. The number of quantization bits is a key factor in the quantization precision of the model. Generally, the higher the number of bits, the better the model precision, but the corresponding model size will also increase. The present invention adopts 8-bit symmetric quantization, that is, each weight is quantized to an 8-bit integer.
[0119] Sparse coding technology: Sparse coding technology reduces the amount of data to be transmitted by only activating important parts in model updates. Let the update vector be dW, and the vector after sparse coding be dW'. Then the sparse coding process can be expressed as:
[0120] dW' = sparse(dW, τ) (14)
[0121] where τ is the threshold for determining which parameters are important, and sparse(·,·) is the sparse coding operation.
[0122] Combined application of coding technologies: Combining model quantization and sparse coding technologies can further reduce the communication overhead of model updates. The combined communication volume C CommCost can be expressed as:
[0123] C CommCost = size(W') + size(dW') (15)
[0124] where the size(·,·) function represents the byte size of the parameters after quantization or sparse coding.
[0125] Update transmission strategy: In the edge-cloud collaborative learning framework, the update transmission strategy needs to consider network bandwidth and communication frequency. An effective strategy is to transmit the quantized and sparsely coded model updates periodically instead of transmitting at each iteration. Let T be the transmission period, then the transmission strategy can be expressed as:
[0126]
[0127] where W t is the model parameter at time step t, and dW' i is the coded model update at time step i.
[0128] Optimization of communication efficiency: To further improve communication efficiency, compressed sensing and information theory technologies can be used to further reduce the amount of data transmitted. In addition, by predicting the distribution of model updates, data can be compressed in advance, thus reducing the computational resources required for decompression in the cloud.
[0129] 2) Main process of applying differential privacy protection mechanism to protect patient privacy:
[0130] Randomized response mechanism: The randomized response mechanism is a technique that introduces random noise during data release or model training to protect personal privacy. Let b be a binary random variable, whose value is 1 representing the true response and 0 representing the false response. The randomized response r can be expressed as:
[0131] r = b + ∈ r (17)
[0132] wherein, ∈ r is the random noise drawn from the distribution.
[0133] Differential privacy constraint: The differential privacy constraint quantifies the amount of information of the parameter using Fisher information and adjusts the noise level in differential privacy accordingly. For each parameter θ j , calculate its Fisher information F(θ j ), and then dynamically adjust the noise σ j according to the magnitude of the Fisher information:
[0134]
[0135] wherein, C g is a constant determined according to the global differential privacy budget ∈ and the security margin δ. In this way, for the parameter with higher Fisher information (i.e., the parameter that has a greater impact on the model output), a smaller noise will be applied to reduce the impact on the model performance.
[0136] Privacy protection performance evaluation: To evaluate the effectiveness of the differential privacy protection mechanism, it is necessary to evaluate the privacy protection performance of the model. This can be achieved by calculating the sensitivity of the model update to any two adjacent data points. The privacy protection performance can be expressed as:
[0137]
[0138] wherein, x and x' are any two adjacent data points, Pr represents the probability distribution, and θ t is the parameter after the t-th iteration.
[0139] Model training and testing are carried out on multiple different data sets (CIFAR-10-C, CIFAR-100-C, and MNIST-M), and the communication overhead and privacy protection performance are evaluated in the simulated end-cloud collaborative learning environment. The experimental results show that the method of the present invention effectively improves the performance and efficiency of the end-cloud collaborative learning system while protecting data privacy. On the above data sets, compared with the existing method DAN, the method of the present invention improves the average accuracy by about 3%, 2%, and 3% respectively.
[0140] It should be understood that although the steps in the above flowcharts are shown sequentially in the direction of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the above flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0141] The above is only the preferred implementation manner of a privacy protection domain adaptation method under the end-cloud collaborative learning framework disclosed by the present invention, and is not used to limit the protection scope of the embodiments of this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiments of this specification shall be included within the protection scope of the embodiments of this specification.
Claims
1. A privacy protection domain adaptation method under a terminal-cloud collaborative learning framework, comprising a terminal device and a cloud server, characterized in that: The steps include: The terminal device collects training data and performs preprocessing to obtain a training data set; The end device uses the domain adaptation mechanism to extract feature data from the training dataset and dynamically adjust the model parameters; The terminal device transmits the feature data to the cloud server, and the cloud server performs model training and updating under the enhanced Transformer model update framework to obtain a trained cloud model; during the training process, the cloud server uses a communication compression strategy to optimize model parameter transmission and applies a differential privacy protection mechanism to protect patient privacy; The cloud server optimizes the trained cloud model through iterative subsampling and reweighting strategies, and sends the optimized model to the end device as the final model; The end device collects the data to be tested and inputs it into the final model to obtain the test results. Specifically, During the training process, the cloud server uses a communication compression strategy to optimize the transmission of model parameters, including the following steps: quantize the model and convert the floating-point parameters into low-precision representations. Let the original model parameters be W and the quantized parameters be W′. The quantization process can be expressed as: Among them, bits represents the number of quantized bits, quantize(·,·) is the quantization operation, is the quantization interval, round(·) is rounded to the nearest integer; Sparse coding technology is used to reduce the amount of data that needs to be transmitted by activating only the important parts of the model update. Let the update vector be dW and the sparsely coded vector be dW′. The sparse coding process can be expressed as: dW′=sparse(dW,τ) (14) where τ is the threshold used to determine which parameters are important, and sparse(·,·) is the sparse coding operation; Combining model quantization and sparse coding technology to reduce the communication overhead of model update, the combined communication volume C CommCost It can be expressed as: C CommCost =size(W′)+size(dW′) (15) Among them, the size(·,·) function represents the byte size of the parameter after quantization or sparse coding; The following steps are also included: Let T be the transmission period, and perform the model update after periodic transmission quantization and sparse coding according to the preset transmission period. The transmission strategy can be expressed as: Among them, W t is the model parameter at time step t, dW′ i is the model update after encoding at time step i; During the training process, the cloud server applies a differential privacy protection mechanism to protect patient privacy, including the following steps: Introduce a random response mechanism in model training, and let b be a binary random variable, whose value is 1 for a true response and 0 for a false response. The random response r can be expressed as: r=b+∈ r (17) Among them, ∈ r is from Random noise drawn from the distribution; The amount of information of the quantized parameters is constrained by differential privacy. For each parameter θ j , calculate its Fisher information F(θ j ), and then dynamically adjust the noise σ according to the size of the Fisher information j : Among them, C g is a constant determined by the global differential privacy budget ∈ and the security margin δ.
2. According to claim 1, the privacy protection domain adaptation method under the end-cloud collaborative learning framework is characterized in that: The preprocessing includes filtering, denoising and normalization.
3. According to claim 1, the privacy protection domain adaptation method under the end-cloud collaborative learning framework is characterized in that: The end device uses the domain adaptation mechanism to extract feature data from the training data set and dynamically adjust the model parameters, including the following steps: The adapter consists of L fully connected layers, each with N l neurons, where l = 1, 2, ..., L, each layer contains the ReLU activation function ReLU (x) = max (0, x), which can perform nonlinear transformation on features. Let the feature vector of the input data be x, and the output of the domain adapter be z, then the forward propagation of the adapter can be expressed as: z=f adapter (x;θ adapter ) =W L ReLU(W L-1 …ReLU(W1x+b1)…+b L-1 )+b L (2) Where, f adapter is a function of the adapter, W l and b l are the weight matrix and bias vector of the lth layer, θ adapter ={W1,b1,…,W L ,b L } is the adapter parameter; Domain Adaptation Loss for Adapters as follows: Among them, domain adaptation loss is the maximum mean difference MMD or KL divergence. When the maximum mean difference MMD is used, z S and z T They are the outputs of the source domain and target domain data after passing through the adapter; Let θ t is the model parameter at the current moment, is the gradient of the current loss function with respect to the model parameters, v t is the momentum term at the current moment, μ is the momentum parameter, then the momentum update rule can be expressed as: Where η is the learning rate; the model parameters are updated according to the momentum term v t+1 To update: i t+1 =θ t -v t+1 (5) Momentum term v t It is usually initialized to the zero vector, that is, v0=0.
4. According to claim 1, the privacy protection domain adaptation method under the end-cloud collaborative learning framework is characterized in that: The cloud server performs model training and updating under the enhanced Transformer model update framework, including the following steps: Build a pre-trained model Transformer based on multi-head attention as a starting point; Input feature data into the pre-trained model for training, and further fine-tune the strategy to adapt to the target task and dataset to obtain the trained cloud model: Introducing the adversarial loss function, the total loss function of the cloud model is Including anti-loss Domain Adaptation Loss And the target task loss of the model Among them, λ1 and λ2 are used to balance the weights of the two losses. is a task-specific loss function, where M is the total number of categories and y c is a vector whose cth element indicates whether the true label is category c, p c is the probability that the model predicts that the sample belongs to category c.
5. According to claim 1, the privacy protection domain adaptation method under the end-cloud collaborative learning framework is characterized in that: The cloud server optimizes the trained cloud model through iterative subsampling and reweighting strategies, including the following steps: By iteratively subsampling from the training dataset and adjusting the sample weights according to the performance of the model on the target distribution, the weight adjustment formula is as follows: Among them, W i,t is the weight of the i-th sample in the t-th iteration, is the model h on sample x i The loss on is the factor by which the learning rate η is scaled by the number of samples n.
Citation Information
Patent Citations
Service providing system and method based on deep learning
CN110084365A
Edge computing-oriented federated learning indoor positioning privacy protection method
CN111866869A